Cross-Agent Authorization Bypass in AgenticMail Allowed Task Enumeration
CVE-2026-57494

7.1HIGH

Key Information:

Vendor
CVE Published:
20 July 2026

What is CVE-2026-57494?

The vulnerability in AgenticMail's API allows a low-privileged authenticated agent to enumerate another agent's tasks by using specific API endpoints. By supplying the target agent's name, an attacker can retrieve sensitive task information, including task IDs and payloads. This compromises the security model as the task IDs, intended to be confidential, can be exploited to manipulate tasks assigned to different agents. The issue arises due to the ability of authenticated agents to discover agent names through the account directory API. Version 0.9.64 of AgenticMail includes a fix to address this vulnerability.

Affected Version(s)

@agenticmail/api < 0.9.64

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.